{"id":"MAL-2026-17485","summary":"Malicious code in css-scroll-anchor-polyfill (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (36596ba9b9d8c0f994abe3cd87783f4f0dc880e63d55374d3555347ce349fab2)\nPackage is published as css-scroll-anchor-polyfill but its index.js is empty and its contents impersonate internal Wix thunderbolt registry module names (thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, editorRegistry, corvidRegistry, and others) with a shipped registry-manifest.min.json mapping them to parastorage.com URLs. The declared purpose (a CSS scroll-anchor polyfill) is unrelated to the shipped code. thunderboltRegistry.js contains a top-level IIFE that executes on require: it runs local reconnaissance via child_process.execSync (cat /etc/hosts, whoami, id, pwd, ifconfig/ip addr, hostname, uname -a) and transmits the collected output together with a beacon (node version, process.platform, pid) via fetch to a hardcoded HTTP endpoint at http://dxpoc.gt.tc/callback.php/ef9ea0e191006f3cc6670720c99c26f3. Any internal build that resolves one of the impersonated thunderbolt names to this public package and requires the corresponding submodule triggers the reconnaissance and exfiltration path.\n","modified":"2026-10-04T23:30:04.795709844Z","published":"2026-10-04T23:14:52Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020890","import_time":"2026-10-04T23:16:30.660101652Z","modified_time":"2026-10-04T23:14:52Z","sha256":"36596ba9b9d8c0f994abe3cd87783f4f0dc880e63d55374d3555347ce349fab2","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/css-scroll-anchor-polyfill/v/1.0.0"}],"affected":[{"package":{"name":"css-scroll-anchor-polyfill","ecosystem":"npm","purl":"pkg:npm/css-scroll-anchor-polyfill"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"718130a5b99df020a6c33438cb7f504aa4bb86672c6caee0744d59b01f7985802ba5f4","path":"thunderboltRegistry.js","sha256":"52502bae08a507aee56838bd56d869c6afb9d16fecb344faf2b8a36912aba1f0"}],"package_integrity":[{"filename":"css-scroll-anchor-polyfill-1.0.0.tgz","hashes":{"sha1":"f8796c49583ab0c011e8ada9a2c63a3245cd552f","sha512_sri":"sha512-ckKQkApTPEK4Thq2VMtVo36YoBRU1pgTo2GV6YKFeIJAUvoUd9hrvBrFP8/LZAj5Ietejx3zHyG6f3XaqLgZSg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/css-scroll-anchor-polyfill/MAL-2026-17485.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}